# Logstash Error : Expected one of #, ", ', -, \[, {, \] at line 4, column 14 (byte 33) after input { file { path =\> \[

**URL:** <https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532>\
**Category:** Logstash\
**Created:** [March 22, 2017, 4:45am UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532 "2017-03-22T04:45:32Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![manopmk](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@manopmk](https://discuss.elastic.co/u/manopmk)\
**Post date:** [March 22, 2017, 4:45am UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/1 "2017-03-22T04:45:32Z")

</div>

Im Using **mac** im **unable to load apache log to logstash.** Im getting error  
" **Error: Expected one of #, ", ', -, [, {,] at line 4, column 14 (byte 33) after input { file { path =\> [**

I tried path =\> "/Users/tcstsb3/Downloads/log/access\_log.log"  
path =\> ["/user....../apache.log"]  
path =\> ["user....../apache.log"]

same error only im getting,  
ANY ONE PLZ HELP ME

**My Conf**

input {  
file { path =\> [“/Users/tcstsb3/Downloads/log/access\_log”] type =\> "apache" }  
}  
filter {  
grok {  
match =\> { “message” =\> “%  
{COMBINEDAPACHELOG}” }  
}  
}  
output {  
elasticsearch { hosts =\> [“10.145.40.24:9200”] }  
stdout { codec =\> rubydebug }  
}

**Note:**  
im using  
logstash 1.4.2  
elastic 1.4.4  
java 8

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 22, 2017, 6:08am UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/2 "2017-03-22T06:08:56Z")

</div>

Make sure you're using regular straight double quotes:

```
"

```

It looks like you're using this kind of quote:

```
“
```

---

<div class="post-metadata">

**Author:** ![manopmk](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@manopmk](https://discuss.elastic.co/u/manopmk)\
**Post date:** [March 22, 2017, 6:59am UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/3 "2017-03-22T06:59:32Z")

</div>

Thank you soo much buddy 🙂  
that error gone.  
but im getting new error

**Using milestone 2 input plugin 'file'. This plugin should be stable, but if you see strange behavior, please let us know! For more information on plugin milestones, see [http://logstash.net/docs/1.4.2/plugin-milestones](http://logstash.net/docs/1.4.2/plugin-milestones) {:level=\>:warn}**  
**Unknown setting 'hosts' for elasticsearch {:level=\>:error}**  
**Error: Something is wrong with your configuration.**

can you help

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 22, 2017, 7:06am UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/4 "2017-03-22T07:06:00Z")

</div>

I strongly suggest that you upgrade your version of Logstash. If you upgrade to at least 2.0 your problem will magically disappear since that version introduced the `hosts` option (replacing the old `host` option).

---

<div class="post-metadata">

**Author:** ![manopmk](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@manopmk](https://discuss.elastic.co/u/manopmk)\
**Post date:** [March 22, 2017, 7:24am UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/5 "2017-03-22T07:24:00Z")

</div>

thanx buddy

Im using mac.  
is there any command to update the version of logstash ?.

have one more query if i update logstash , whether i need to update elasticsearch and kibana ?.  
currently using elasticsearch (1.4.4) kibana (4.0.1) ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 22, 2017, 7:27am UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/6 "2017-03-22T07:27:09Z")

</div>

> is there any command to update the version of logstash ?.

That depends on how you installed it.

> have one more query if i update logstash , whether i need to update elasticsearch and kibana ?.  
> currently using elasticsearch (1.4.4) kibana (4.0.1) ?

Logstash 5.x probably works with ES 1.4 but it's probably not a well-tested combination. Logstash 2.x will definitely be fine.

---

<div class="post-metadata">

**Author:** ![manopmk](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@manopmk](https://discuss.elastic.co/u/manopmk)\
**Post date:** [March 22, 2017, 7:33am UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/7 "2017-03-22T07:33:02Z")

</div>

Thank you buddy 🙂

some how i managed existing version make configuration to work by **elasticsearch {**  
\*\* host =\> "10.145.40.24"\*\*  
\*\* port =\> "9200"\*\*  
\*\* protocol =\> "http" }\*\*

now im getting this message

**Faraday::TimeoutError: Timeout::Error**  
\*\* call at /Users/tcstsb3/Downloads/elkpack/logstash/vendor/bundle/jruby/1.9/gems/faraday-0.9.0/lib/faraday/adapter/net\_http.rb:56\*\*  
\*\* build\_response at /Users/tcstsb3/Downloads/elkpack/logstash/vendor/bundle/jruby/1.9/gems/faraday-0.9.0/lib/faraday/rack\_builder.rb:139\*\*  
\*\* run\_request at /Users/tcstsb3/Downloads/elkpack/logstash/vendor/bundle/jruby/1.9/gems/faraday-0.9.0/lib/faraday/connection.rb:377\*\*  
\*\* perform\_request at /Users/tcstsb3/Downloads/elkpack/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.1/lib/elasticsearch/transport/transport/http/faraday.rb:24\*\*  
\*\* call at org/jruby/RubyProc.java:271\*\*  
\*\* perform\_request at /Users/tcstsb3/Downloads/elkpack/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.1/lib/elasticsearch/transport/transport/base.rb:187\*\*  
\*\* perform\_request at /Users/tcstsb3/Downloads/elkpack/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.1/lib/elasticsearch/transport/transport/http/faraday.rb:20\*\*  
\*\* perform\_request at /Users/tcstsb3/Downloads/elkpack/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.1/lib/elasticsearch/transport/client.rb:102\*\*  
\*\* perform\_request at /Users/tcstsb3/Downloads/elkpack/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-api-1.0.1/lib/elasticsearch/api/namespace/common.rb:21\*\*  
\*\* get\_template at /Users/tcstsb3/Downloads/elkpack/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-api-1.0.1/lib/elasticsearch/api/actions/indices/get\_template.rb:24\*\*  
\*\* template\_exists? at /Users/tcstsb3/Downloads/elkpack/logstash/lib/logstash/outputs/elasticsearch/protocol.rb:132\*\*  
\*\* template\_install at /Users/tcstsb3/Downloads/elkpack/logstash/lib/logstash/outputs/elasticsearch/protocol.rb:21\*\*  
\*\* register at /Users/tcstsb3/Downloads/elkpack/logstash/lib/logstash/outputs/elasticsearch.rb:259\*\*  
\*\* each at org/jruby/RubyArray.java:1613\*\*  
\*\* outputworker at /Users/tcstsb3/Downloads/elkpack/logstash/lib/logstash/pipeline.rb:220\*\*  
\*\* start\_outputs at /Users/tcstsb3/Downloads/elkpack/logstash/lib/logstash/pipeline.rb:152\*\*

i Dont know whether configuration loaded or not  
how to check buddy .

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 22, 2017, 7:34am UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/8 "2017-03-22T07:34:19Z")

</div>

Looks like a network problem. Make sure you can connect to 10.145.40.24:9200.

---

<div class="post-metadata">

**Author:** ![manopmk](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@manopmk](https://discuss.elastic.co/u/manopmk)\
**Post date:** [March 22, 2017, 7:37am UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/9 "2017-03-22T07:37:32Z")

</div>

i tried in browser "[http://10.145.40.24:9200/](http://10.145.40.24:9200/)"

its work fine.  
im getting response

{  
"status" : 200,  
"name" : "Doug Ramsey",  
"cluster\_name" : "elasticsearch",  
"version" : {  
"number" : "1.4.4",  
"build\_hash" : "c88f77ffc81301dfa9dfd81ca2232f09588bd512",  
"build\_timestamp" : "2015-02-19T13:05:36Z",  
"build\_snapshot" : false,  
"lucene\_version" : "4.10.3"  
},  
"tagline" : "You Know, for Search"  
}

then how can i check that configuration is loaded in logstash or not buddy.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 22, 2017, 7:40am UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/10 "2017-03-22T07:40:14Z")

</div>

The configuration is loaded, otherwise you wouldn't get this far. I don't know why Logstash is having problems. Keep in mind that your browser could have proxy settings that affect the results. Use a low-level tool like telnet instead. Over and out.

---

<div class="post-metadata">

**Author:** ![manopmk](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@manopmk](https://discuss.elastic.co/u/manopmk)\
**Post date:** [March 22, 2017, 1:46pm UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/11 "2017-03-22T13:46:04Z")

</div>

Buddy  
finally i cleared all error

**my conf**  
input {

file {   
path =\> ["/Users/tcstsb3/Downloads/log/access\_log.log"]  
type =\> "apache"  
}

}

filter {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
}  
}

output {  
elasticsearch {  
host =\> "10.145.40.24"  
port =\> "9200"  
user =\> "username"  
password =\> "password"  
protocol =\> "http"  
index =\> "test"  
}

stdout { codec =\> rubydebug }  
}  
i executed file by ./logstash -f apache.conf  
it shows " **Logstash startup completed**"  
i opened kibana 4  
under settting , i created index called test (which i configured in conf) choosed timestamp.

then im unable to see the access\_log under discover tab  
can you help me

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 22, 2017, 1:56pm UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/12 "2017-03-22T13:56:59Z")

</div>

Logstash is tailing the file and probably waiting for more data to be added. Read the file input plugin documentation and pay close attention to the `start_position` and `sincedb_path` options.

---

<div class="post-metadata">

**Author:** ![manopmk](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@manopmk](https://discuss.elastic.co/u/manopmk)\
**Post date:** [March 22, 2017, 2:15pm UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/13 "2017-03-22T14:15:45Z")

</div>

Hi Buddy i have added some input field

now im getting this error in kibana

**Error: Could not locate that index-pattern (id: logstash-\*) in kibana**

---

<div class="post-metadata">

**Author:** ![manopmk](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@manopmk](https://discuss.elastic.co/u/manopmk)\
**Post date:** [March 23, 2017, 7:00am UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/14 "2017-03-23T07:00:39Z")

</div>

im using kibana 4.0.1  
under Selected Fields

**This field is present in your elasticsearch mapping but not in any documents in the search results. You may still be able to visualize or search on it.**

Didnt show any log which i configured

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2017, 7:00am UTC](https://discuss.elastic.co/t/logstash-error-expected-one-of-at-line-4-column-14-byte-33-after-input-file-path/79532/15 "2017-04-20T07:00:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
